Back to all lessons
Awareness Lessons
last month

Social Engineering via Third-Party Contractor Exposes 4.1M Healthcare Records

The AdaptHealth breach demonstrates the critical risk posed by third-party contractors who have privileged access to sensitive healthcare systems. ShinyHunters exploited a compromised contractor account through social engineering — a human-focused attack vector that bypasses technical defenses entirely. Healthcare organizations are high-value targets because they hold both financial and medical data, making robust third-party access governance essential. This incident highlights that an organization's security posture is only as strong as its weakest external partner.

Tactical Insight

Immediate actions

  • Audit and revoke unnecessary third-party contractor access privileges, applying least-privilege principles across all vendor accounts.
  • Enforce phishing-resistant MFA (e.g., FIDO2/hardware keys) on all contractor and vendor accounts accessing sensitive systems.
  • Conduct emergency social engineering awareness training for all staff and contractors with system access.

Long-term improvements

  • Implement a formal third-party risk management (TPRM) program that includes regular security assessments and contractual security obligations for all vendors.
  • Deploy Privileged Access Management (PAM) solutions to monitor, record, and time-limit contractor sessions.
  • Establish zero-trust network access controls so contractor accounts can only reach the specific systems required for their role.

Detection measures

  • Enable anomaly-based alerting on contractor account behavior, including unusual login times, locations, or data access volumes.
  • Require contractors to operate through isolated, monitored jump servers to create a full audit trail of all activity.
  • Implement continuous identity threat detection (ITDR) to flag account compromise indicators such as credential stuffing or impossible travel.